Aquaris E4.5 Ubuntu Edition
bq.com
bq.com
Let's hope the phone shows up :)
I guess we will have to wait/help/contribute a lot to get it closer to an acceptable quality level.
In the meantime, I wonder if there is any way to install Android on the Ubuntu Edition E4.5.
Please can you share the bugs so that others can actually judge usability for themselves? Have you filed the bugs?
No, you really don't. Because if that was the case, instead commenting here, why won't you go to Ubuntu phone bug tracking or whatever and give your feedback there where would be actually useful? Just a though.
The one thing I do not like is the runtime of the battery. 44 hours was the absolute maximum I had this phone running before it went black (just turning it on, entering the SIM-PIN, having Bluetooth, GPS and WiFi turned off and doing nothing else). In my typical usage pattern, a runtime of 24 hours is the more realistic value. Have to load it every day :-(
Sometimes I come in and crash without putting it on the charger and realize what I've done the next morning. When that happens, I don't have to worry about immediately charging it even then; usually it still can make it to the end of that day (business hours) without being on a charger. This happens around once a week or so, maybe more sometimes.
I'm on my second Moto G, and this has been true for both, so it's not a one-off thing.
However, it looks like you should be able to get Kitkat on this easily[1].
[1] http://www.bq.com/gb/products/aquaris-e4-5.html Search for "android"
Are you happy with it ?
It just amazes me how cheap tech has become. The other day I was looking through the Microsoft Store, saw a $90 ish tablet that had various discounts at times bringing it down to an absolutely ridiculous $60-70 range. I checked out some reviews and they were glowing (in terms of value), it actually runs windows 8 and comes with a year of Office 365 and an hour of Skype minutes every month. I can hardly imagine anyone buying Office 365 for a year at $70, instead of just buying this tablet instead haha. Of course it's no Mac Pro, but it surprised me.
HP stream 7 was the name. I just sat there grinning while watching the reviews on this device, computing is truly becoming completely and totally ubiquitous this decade, even consumer computing is becoming a cheap commodity.
[1] Read about Modu in TechCrunch some years ago. An Israeli startup backed by Yossi Vardi, IIRC. Not sure what happened to it. But the idea seemed promising.
Also the battery dies on you quickly on idle, and it doesn't charge that easily through usb, you need a really high power charger for the charging indicator to turn on.
Are netbooks still being produced in mass scale? I was considering buying a netbook recently, as a 2nd lighter machine than my laptop, so that I can take it when I go out to nearby places like for shops / malls, and use short spells of free time outside to do some work (at least work that's light on CPU/RAM resources, like Python programming, or even email or technical topic browsing). But a few computer shops I went to, told me that Asus / Acer (for example) are not making new ones these days. This is in India, BTW. Don't know if this issue (if real) is specific to this region or not.
And while it was already large two decades ago, it's not ubiquitous in the sense of finding $70 star trek like tablets in remote villages in central Africa, like happens today. Ubiquitous in the sense that outside of the 10-20% upper-middle class of the US/Europe, who've indeed had personal computing for decades, we're seeing computing arrive en masse to an additional 1-2 billion people, and probably billions more not long after, now that you get full desktop software, with complete hardware including input and a screen and battery, at $70 retail, and sub $50 second hand. That's insane.
You guys remember the $20 smartphone media talk last year? Should have arrived by now. In any case, this decade is something special. Chips are using so little energy nowadays, low res screens, too. Things are sturdy, cheap. The electricity costs per year are a tiny fraction of the device's costs (which is on its way to 5 to 10c a day per device) Computing is actually going to become accessible to 4-5 billion people by the end of the decade, that's something really new. And we're seeing a lot of initiatives in terms of free, global-coverage connectivity in the form of internet, too, for low-data applications like messaging, banking, wikipedia etc. e.g. FB & Google's initiatives.
1. https://news.ycombinator.com/item?id=9225691
2. https://github.com/bq/aquaris-E4.5/commit/34cf494bca625acad0...
That does sound fairly crazy, but it may well be that's more sensible than it sounds in parts of Europe, for instance Spain, where the early adopters won't have the same money as they do in the US, and the iPhone is expensive enough as to be almost nowhere to be seen.
Seems quite different from FirefoxOS, who have a much more pointed strategy of radically undercutting price, and targeting markets in the developing world.
Pretty useless comment, I know.
(or did you mean the ereader? Not tried, sorry)
I found this[0] but it is in Spanish, and many of the links to source don't go anywhere. It seems like they us Debian and Qt, which would be very neat.
[0]: http://www.mibqyyo.com/actualidad/2013/07/10/programa-de-des...
That links to an English version of the page you found: http://www.mibqyyo.com/actualidad/2014/01/08/bq-ereaders-dev...
Note that I don't have the device so I don't know if this works, but if there are problems with the instructions I assume BQ would help (since the open sourceness is a selling point).
The specs of that particular one show no bluetooth (and no OTG usb), so can't connect a keyboard.
It also has no wireless apart from wifi; and only 512MB (though that's plenty for ssh!)
Also, difficult schmifficult! I bet ed, the standard editor, will work just fine. Shouldn't be much worse than, say, a 300 baud terminal!
Beats a line printer! Can relate - I'm ecstatic that (70s era) unix utilities are blazing instant on a phone. I'm sure vim would also work on an e-reader, if you don't need to find the cursor.
I should research this. Working on e-ink/e-paper would be so much better on the eyes - and incredible battery life (they claim 2 months for the Kindle).
[0] http://www.engadget.com/2012/02/23/hack-enables-fast-refresh...
Is there a Terminal app with a local shell?
I'm in the US, so I can't get this one, but these are what I'm hoping for when it gets here.
What's nice is that it's just a regular Ubuntu shell prompt, not a hacked up one like you get on Android. All the usual stuff you expect to have is there. The Terminal app integrates nicely too - for example if you use less, then swiping up and down scrolls up and down.
Note though that by default the root filesystem is read-only. You can make it read-write, but then the image-based OTA updates aren't expected to work and of course if you break things you get to keep all the pieces. For this reason I've avoided doing this for now, but it's nice to know that I can do it. I expect I'll probably end up rolling my own customized images instead in order to keep my phone more reliable.
Not sure how the phone version of Ubuntu is versioned (http://www.ubuntu.com/phone didn't help), though.
Anyway, those phones or tablets that turn into supposed regular computers are cool, but at the end of the day when I have access to a screen and keyboard there is usually a computer not far. Since my data is in the cloud anyway, I'd rather use that separate computer than my phone.
And I very frequently find myself in situations where the network connection is so poor that streaming my data over the network is an exercise in frustration.
When I then walk around with more and more powerful computers in my pocket, it's great to be able to make use of it.
EDIT: Just noticed that the sale is only available in the Spanish store. The German one still shows "It will be available shortly".
> Compatible formats
> Text format .txt/ .pdf/ .xls/ .doc/ .ppt
No .odt?
That said, I'd love to sit down and play with the OS on the phone to see what it does different from other mobile OSes today.
If so, I might get that one and install Ubuntu myself.
Which ones? I had the same experience with the ZTE Open C but found great community updates for this and other phones. Open C updates are this way: http://builds.firefoxos.mozfr.org/doc/en/devices/zte-open-c
Why FirefoxOS phones there? Because they don't draw much attention, they are cheap, and reliable for basic phone needs - calling, texting, even some browsing. Also the battery life is pretty good.
They are bit sluggish, but still much faster than other cheap phones.
Meanwhile my iPad 2 is still getting the latest iOS version multiple times each year...
What carrier/phone do you have?
Shame that this phone has such a low res screen or I'd be tempted.
All this introduction is to try to understand the Ubuntu Phone world, I don't think it can emerge against Android or iPhone, so it should definitely compete against Mozilla in emerging markets, but it looks like is coming a little bit late. I am also curious about how developers will react to the platform, with a native or HTML5 approach, looks similar to the Microsoft strategy. Firefox was able to get devs easily because the HTML5/Javascript is an easy combo and is widely known, native development requires more efforts and has a steeper learning curve. A smartphone is 20% platform and 80% ecosystem, no apps means no users.
I am honestly interested in trying it, I did it for Firefox, writing a simple weather app for it, so I would like to do the same. At the moment, I am not sure the system will be able to compete, but happy to be proven wrong!
Also shipping comes around 25€ in Europe. Quite steep for a phone priced at 169€.
[1] http://arstechnica.com/apple/2012/07/recyclers-disagree-on-i...
> Originally, "lithium polymer" stood for a developing technology using a polymer electrolyte instead of the more common liquid electrolyte.
> The second meaning appeared when some manufacturers started applying the "polymer" denomination to lithium-ion cells in pouch format.
The first one (polymer bag around a lithium ion battery) is currently used in many devices, but the second (polymer electrolyte) is not commonly used and seems to be an active area of research.
http://en.wikipedia.org/wiki/Lithium_polymer_battery
The (common) Lithium Polymer batteries are, according to the Wikipedia page, as safe (or unsafe) as Lithium Ion batteries.
On HSPA+ (H+) my connection is fast enough for any purpose besides downloading movies, and it's not like I've got unlimited data. Even 3g's theoretical speed is great if they could get that to work for a change.
I have 4g on a company laptop and the speed is better than many places' WiFi, but I have yet to find an excuse to use it (someone has to pay that data bill). It's not like I don't know how fast it really is, I just don't see the point of it right now. In 5 years 3g really will be too slow for many applications, but as it stands...
You answered your own question. It's progress, and the sooner people around the world adopt 4G, the sooner it becomes the standard, just like 3G before it.
But in 5 years, in all reasonableness, you'd have a new phone. Having no lte on this one doesn't change much. That's what I meant to say.
additionally contention levels are just horrible on the 3g services. what's that 20 Kb/s and 40% packet loss just because you were silly enough to use it near a train station.
It contends better too, which affects everyone.
I have unlimited LTE for £15/mo (Three UK) so I don't need to worry about paying for the data.
[1] https://translate.google.com/translate?sl=es&tl=en&js=y&prev...
Sarcasm aside: I am still waiting for an official FFOS Whatsapp version, meanwhile I am using my ZTE Open as a PC+camera+GCM dongle to run some fun hacks, kindda like a Tessel Machine.
If I'm a business with a valid VAT number outside Spain, I shouldn't pay the VAT, right?
Wi-Fi 802.11 b/g/n Bluetooth® 4.0, Bluetooth® 4.0 hardware compatibility (software not currently integrated). 2G GSM (850/900/1800/1900) 3G HSPA+ (900/2100) GPS and A-GPS
There is a lot of relevant information inside that bar.
"Telegram is the most secure way to..." or http://www.bq.com/flexy_templates/game/assets/en/screen-3.pn...
If you market your phone towards nerds, don't bullshit us with crypto marketing.
However, due to how much of an awful botch job the protocol is, even if the server was FLOSS, it would still be untrustable.
MTProto has... issues. It uses IGE (infinite garble extension, a variation on the accumulated block chaining - ABC - mode of operation) as its mode of operation, which isn't exactly widely used or battle proven and is considered broken. Something like GCM wouldn've been a saner choice. Another issue is that it uses SHA1 for message authentication. Now, the issue isn't so much that they're using SHA1, but that they aren't using a MAC for message authentication.
It has other issues, but I have to rush off.
If you’ve created HTML5 apps or mobile websites for
other platforms — there’s good news: the path
to Ubuntu
couldn’t
be quicker. We support both the Webkit/Blink and
Cordova development standards — and with a separate
API that enables
websites to be quickly converted to run independently
of a browser, with full access to phone notifications
and
settings, the same goes for your web applications.Just ask Microsoft.
These phones will never compete with the Android or iOS App ecosystem, but they will have:
* Productivity apps that cross from desktop to mobile
* A relatively small number of native mobile-only Apps
* Web Apps
And that may well be enough.
Edit: Here's a list of the "core apps". https://wiki.ubuntu.com/Touch/CoreApps Notably missing are email and SMS apps, so I'm not sure what they're using for those.
Also, you won't spend as much time in siloed app experiences on this OS. It's all about Scopes: http://www.ubuntu.com/phone/features
Email is Dekko: https://launchpad.net/dekko (No idea about the name.) Based on (forked from) Trojitá.
I haven't seen a maps app, but I know they're using Here/Nokia for location services (https://insights.ubuntu.com/2014/07/30/nokia-here-maps-comin...). I think the BQ phone comes with a location "scope". The Here HTML5 app is pretty good on FxOS, so they could be using that.
- ring an alarm when in 'off' state
- change their IMEI
I'm not claiming that everyone needs that or that it will be possible on Ubuntu; just reminding that MTK chips have some unique advantages, too.
Unless anyone knows that's changed in recent years?
I would prefer more open hardware and will vote with my wallet if there's something open of reasonable price/performance, but I choose to be pragmatic about it. In this space, even getting something I can run a non-locked down Linux on is an improvement.
No https:// by default. Again, if you market this as towards the nerdy audience: Put _everything_ behind HTTPS. I simply do not want to let others know, what phone I might buy.
Thank you.
The only sane solution is to set up HTTP to redirect to HTTPS, and add an HSTS cookie.
$ openssl genrsa -out $server.key 2048
$ openssl req -new -sha256 -key $server.key -out $server.csr
Get the CSR to a CA and get the cert in your email inbox. Compose the cert into a chain (the most painful part of the process).Put the cert and the key in /etc/ssl/certs/example.com.crt and respectively /etc/ssl/private/example.com.key;
In your nginx config add the following:
server {
listen 443 ssl spdy;
server_name www.example.com
ssl on;
ssl_session_timeout 5m;
ssl_session_cache shared:SSL:5m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';
ssl_prefer_server_ciphers on;
# HSTS (ngx_http_headers_module is required) (15768000 seconds = 6 months)
add_header Strict-Transport-Security max-age=15768000;
resolver 8.8.8.8;
ssl_certificate /etc/ssl/certs/example.com.crt;
ssl_certificate_key /etc/ssl/private/example.com.key;
#...
}
Restart nginx. If you want to only do HTTPS, and have HTTP redirect to HTTPS: server {
listen 80 default_server;
server_name _;
rewrite ^ https://www.example.com$request_uri permanent;
}
It took 3 minutes to write this comment. Getting a new cert up and running will take you $5 and 15 minutes if you follow these instructions. Free if you use startssl.com. Cheapest wildcard I found was https://www.ssls.com/ when they ran a sale: $42. Current cheapest Google turned up was https://cheapsslsecurity.com/sslproducts/wildcardssl.html for $60. Personally, I prefer wildcard certs whenever possible, free certs from startssl.com.All web servers just do HTTP by default.
That, and shared hosts.
The browser should treat any HTTP connection as a MITM attack at all times, too. Actually, it should also treat it as multiple MITM because everyone in your network or in the path can see your traffic.
We could argue if it even makes sense to differentiate between SSL with self-signed certs and plain HTTP connections when warning users, I'll give you that. But in no way SSL with self-signed are worse than HTTP.
> Try to think through how else it could possibly work, and you'll see why the browsers do this.
Funny :)
Allowing access on both http and https is indeed a bad practice, but not in regards to the scenario you described.
The scenario you described has been covered since long by the 'secure' attribute, available when creating cookies. Assuming the authentication was performed from within the https channel, the cookie won't be disclosed when requests are triggered on the http channel. This covers the 'Reddit' case from an application layer perspective.
The vulnerability is rather in browsers (such as Firefox). They allow the rewriting of an existing cookie value through the http channel, although it was originally set through the https channel. This is a huge problem and I still don't understand why this isn't reported by any researcher as a critical security flaw...
Let's not forget that from Reddit's point of view, the browsing of the public content is not confidential, hence no need to hide it. Only your credentials are confidential, hence their transmission is configured to happen through a secure channel by default (if you're lucky). As long as it matches their security policy, it is not a vulnerability, per say. The vulnerability here is that Reddit 1) accepts authentication events sent through HTTP and that 2) Reddit keeps considering accounts as reliable after a successful HTTP authentication. We could also argue on the quite insignificant consequences of your Reddit account being hacked (for most users) in opposition to the disclosure of a password that you have not used anywhere else (isn't it?).
As a user, you believe that the Reddit pages you browse should be private, which led you to conclude Reddit is flawed. I agree that Reddit users' traffic should be kept private. But, we are still in an era where information security is defined by the expectations of corporations, not those of customers/users. The total cost induced by the fact that anyone on the same network as you can see your Reddit traffic remains lower than improving the security of the platform.
If you want Reddit to consider this as a "vulnerability", you need to either convince lots of users to stop using Reddit until they fix this (traffic volume pressure) or convince loud people to start shaming their owners on large audience news sites (shame pressure). These two strategies are the only ones that work, to my knowledge. As long as their business keeps running and there is no shamming, they don't have any real incentive to pull the source code and fix this: it's not a major security vulnerability. (the fact that browsers overwrite https cookies from http responses is a major one, though...)
Even if Reddit allowed you to log in via HTTPS only and kept your session cookie secure, but let you browse anonymously over HTTP, they'd still be leaking info about what you are browsing, as you said. I agree, this is a problem for the user. Say, the user is looking at topics about maternity leave while her boss doesn't know she is pregnant. What can the boss do with this info? Or say the user is looking into methadone clinic experiences at work?
Browsing over HTTP also lets an attacker inject content. Ads are the obvious and somewhat innocuous case, but think about the phishing opportunities here. "Please log in to proceed" with a form that submits the password to the attacker.
You are right they won't change until either their users start complaining, or something really bad happens as a result of this negligence, but I am simply using them as an example of a pretty widespread issue. Lots of sites do this and it's very unfortunate.
This is the responsibility of the admin, not the user.
What if I live in Spain and only speak English. What if I live in a Catalan region and want Catalan? What if I live in GB and want to read it in Spanish as it's my first language?
With the world being as global as it is and people readily moving around, geographic location does not equal language preference.
Ideally the site would have geographic specific sections but allow all languages it has translations for in each section. Bonus points if you default language based on my HTTP headers and allow session based overrides.
Every Catalan (or Galician, Valencian, Basque) speaks Spanish, as do the vast majority of the expats I know (and I'm one myself).
You can still access the specific site of the language you are interested in. Or, in the worst case, use Google translate.
I've been doing eCommerce for a long time now and the number of site that realize this is shockingly limited.
With a few exceptions, the translations you are using for a country website's language are possible to use for any country where a visitor wants to use the language. Exceptions include things like country specific product features and such. Those kinds of things would need a little though.
The data is all there and the tech is all there. It's just a desire or realization that is missing.
But apart from the data and tech you need people implementing it, and I can understand most companies not seeing covering your/our case as worty of the added development/maintenance cost that it would entail.
Your browser already tells every website what language(s) you speak in the Accept-Language header, so it's not like that information isn't available.
Still, I would imagine major e-commerce websites to add support for a langugage in the website, if the potential userbase is big enough (for example, the Apple Store does).
My knowledge of India is very limited , but it always seemed to me that the unifying language really is English (again, from a very cursory glance, Amazon, Apple and HP have Indian e-commerce stores in English).
My point is that decoupling language and location as a general feature does not make much economic sense in the vast majority of cases.
This is especially true for major e-commerce sites: think about Amazon, and the number of items being sold (millions ?). Many of those are sold only in a particular store, or have variations between a store and another: how much would it cost to translate all the articles for all the stores in x languages ?
Some of those regions are known for being proud of their language and culture, so in case of similar specs and cost many people will chose a vendor that covers their native (or L2 but local) language instead of one that doesn't. Something to take into account is that e.g. Catalan (or Valencian or Balearic, you name it) represents between ~9M and ~11M native and L2 speakers (depending on sources). What else... Oh yes, the regions where Catalan is official in Spain are among the wealthiest when considering the average income for its residents. That sounds like a good pond to fish for early adopters. Basques with even less population (and less L1 and L2 speakers, even in % than Catalans) are also among the wealthiest. The use case doesn't seem that narrow anymore, doesn't it?
Every single big company in Spain is able to communicate in any official language. Dude, it means business!
Finally, and I'm leaving a lot of stuff behind, people are usually not very thick skinned and calling the support of these languages "very limited use case" could be considered, well... inconsiderate at least.
Other companies are MUCH worse. Apple and Google being good examples. Try either being in the US or having a US credit card and purchasing in the EU. Nightmare!
...and GB = Great Britain.
Just my 2¢.
Maybe HN's mods can fix that. I tried to editing it but while you can edit the title and/or add text, you can't edit the URL (which makes sense, actually).
Sorry guys.